PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/onboard.php +17 -4 1.0.14 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Staffs;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Utils\Singleton;
10 12
11 13 /**
12 14 * Onboard Class
@@ -38,14 +40,25 @@
38 40 *
39 41 * @return void
40 42 */
41 43 public function setup_onboard_page() {
42 - $page = isset( $_GET['page'] ) ? sanitize_text_field( $_GET['page'] ) : '';
44 + // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- Read-only page parameter check, no form processing
45 + $page = isset( $_GET['page'] ) ? sanitize_text_field( wp_unslash( $_GET['page'] ) ) : '';
43 46
44 47 if ( 'staff-onboard' !== $page ) {
45 48 return;
46 49 }
47 - ob_start();
48 - include_once TIMETICS_PLUGIN_DIR . '/templates/staff/onboard.php';
49 - exit();
50 +
51 + $template = TIMETICS_PLUGIN_DIR . '/templates/staff/onboard.php';
52 +
53 + if ( file_exists( $template ) ) {
54 + include $template;
55 + }
56 +
57 + $output = ob_get_clean();
58 +
59 + // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
60 + echo $output;
61 +
62 + exit;
50 63 }
51 64 }